lulo

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Anomaly
AnomalyLOW
templates/lulo-client.ts

No clear evidence of embedded malware or intentional obfuscation in this module. However, the module presents a significant supply-chain/behavioral risk: it signs and broadcasts server-generated Solana transactions provided by a remote API without local validation that they match the caller’s requested mint/amount/depositType/withdrawType or expected on-chain instructions. If the upstream API response is malicious/compromised or the transport is manipulated, this client can unintentionally authorize unintended transfers using the user’s wallet. Additional secondary risks include unvalidated filePath handling in fromKeypairFile() and potential leakage of API error payloads through thrown exceptions.

Confidence: 62%Severity: 60%
Audit Metadata
Analyzed At
Sep 14, 2026, 10:08 PM
Package URL
pkg:socket/skills-sh/sendaifun%2Fskills%2Flulo%2F@691cebe52b077af0a545a572441f63a0f31e3999fe995feeae9b1858e7ddafb7
Security Audit — socket — lulo